Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
6.4
CVE-2026-9626
- EPSS 0.22%
- Veröffentlicht 03.07.2026 04:30:19
- Zuletzt bearbeitet 06.07.2026 18:02:49
The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and including, 4.1.0 This is due to insufficient input sanitization in the post_commen...
9.8
CVE-2024-6624
- EPSS 2.87%
- Veröffentlicht 11.07.2024 07:15:06
- Zuletzt bearbeitet 08.04.2026 19:22:12
The JSON API User plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.9.3. This is due to improper controls on custom user meta fields. This makes it possible for unauthenticated attackers to register as...
1